L.P.H. van Belle belle at bazuin.nl
Fri Aug 28 06:29:23 UTC 2015

>We *require*, not desire, but *require* OpenLDAP.  OpenLDAP is used
>for, amongst other things, a Corporate email address book and by the
>RADIUS server. 

wel.. same here, But you can use the ldap of samba,.. i dont see you problem.. 
coperate e-mail adresses in ldap, wel.. i use zarafa mail server, 
which is integrated in ldap also. i extended the schema of samba for that. 
i now have multiple adresbooks and other "trick" accounts and/or users/group
for other things. 
as by example one of my postfix configs. 
server_host = ldap://dc1.internal.domain.tld:389 ldap://dc2.internal.domain.tld:389
search_base = OU=General-Aliasses,OU=Company,DC=internal,DC=domain,DC=tld
version = 3
bind = yes
bind_dn = CN=ldap-bind,OU=Service-Accounts,OU=Company,DC=internal,DC=domain,DC=tld
bind_pw = MyVerySecretPassword

scope = sub
query_filter = (&(objectClass=contact)(displayName=%s))
result_attribute = description
Here in this case for example, i create a contact, and use the displayName and results in description.

and for my users an other filter like.. 
query_filter = (&(objectClass=person)(zarafaAccount=1)(|(mail=%s)(otherMailbox=%s)))
result_attribute = mail

so, again, if needed extend you schema and enjoy your samba AD.. 

go here :
scrol to the bottem, there are also other examples 
here is your radius setup example. 



